· intuitem · News  · 3 min read

What's New in CISO Assistant — Week 16, 2026 (v3.15.8 – v3.15.9)

Container hardening, Cyfun 2025 scoring and export, richer import/export across TPRM, findings and risk assessments, DORA subcontracting chains, and a wave of UX polish.

Container hardening, Cyfun 2025 scoring and export, richer import/export across TPRM, findings and risk assessments, DORA subcontracting chains, and a wave of UX polish.

Two releases this week focus on hardening the platform, extending import/export coverage, and refining day-to-day workflows.

Container Hardening

Hardened container images (v3.15.8) — A long-running initiative lands: CISO Assistant containers have been hardened across the board. The enterprise edition was then realigned on top of the community edition so both editions share the same hardening baseline (v3.15.9).

Cyfun 2025

  • Average-of-averages scoring logic (v3.15.8) — A revised scoring approach to match Cyfun 2025 expectations, so scores computed in CISO Assistant match what the framework actually specifies.
  • Cyfun audit export (v3.15.9) — Audits can now be exported directly in Cyfun format.

Import / Export

A broad round of import/export work across several modules:

  • TPRM exports (v3.15.8) — Third-party risk management data can now be exported for reporting and archival.
  • DORA — subcontracting chains in ROI exports (v3.15.8) — The Register of Information export now correctly handles multi-level subcontracting chains.
  • Sanitized finding export for round-trip (v3.15.9) — Finding exports are cleaned up so they can be re-imported without churn.
  • Risk assessment import/export update (v3.15.9) — Refreshed format and handling for risk assessment data.
  • CSV export — applied control “impact” attribute (v3.15.8) — Fixes a regression where the impact field was missing or incorrect in CSV exports.

Task Email Templates

Richer task notifications (v3.15.9) — Task emails now include direct links and a detailed task list, so recipients can jump straight into the work without hunting through the UI.

EBIOS RM & Risk

  • Navigate back to parent study (v3.15.9) — A new button in the strategic scenario detail view takes you back to the parent EBIOS study.
  • Vulnerabilities linked to follow-ups (v3.15.9) — The data wizard now relates vulnerabilities to the follow-ups they generate.
  • Exception model — link attribute (v3.15.9) — Exceptions can now carry a link, useful for referencing the approving ticket, document, or decision record.
  • CRQ Studies — Executive Summary fix (v3.15.8) — Fixes an error retrieving authors’ emails that prevented the Executive Summary from loading.

UX Improvements

  • Asset graph — sorted domains and multi-level filtering (v3.15.9) — Domains in the asset graph are now sorted, and multi-level domain filtering behaves correctly.
  • Restored sidebar entries (v3.15.9) — Presets and the tasks review entries are back in the sidebar after a regression.
  • autocompleteSelect — match instead of partial text (v3.15.8) — Selecting an existing item now actually selects it, rather than leaving partial text behind. Thanks to @tchoumi313 for this fix.
  • Matrix browser error fix (v3.15.8) — Prevents a browser-side error on certain matrix configurations.

CLI

  • --name flag for assessments (v3.15.9) — Name assessments directly from the CLI.

Internationalisation

  • French currencyHelpText typo fix (v3.15.9) — Small but welcome polish.

Dependencies

  • pytest 9.0.2 → 9.0.3 (v3.15.8) — Rolled out across the backend, enterprise backend, and dispatcher.

For full details, check out the v3.15.8 and v3.15.9 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

v4.1.0 brings a large rework of the EBIOS RM module (study framing, RO/TO radar, standard and advanced likelihood methods on kill-chain steps), arithmetic in workflows with a CEL compute action, MCP write tools for a full risk review, a delegated user-creator role, entity-assessment exports, the BSI C5:2026 framework, German email templates, and a breaking change to the current-user API.

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

v4.0.7 brings an in-app notification centre, a risk trajectory view that plays a risk assessment forward in time, X-rays that cover governance and operations and point at active controls with no evidence behind them, per-user module visibility, Mermaid diagrams in documents and PDFs, and workflows that can draft and review documents.

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

v4.0.5 lands a mapping table beside the graph, relation graphs on detail pages, a command palette that can now search and create, workflow steps that record measurements and file scan results — and a Power BI connector release that anyone who upgraded to 4.0 needs to install. v4.0.6 follows with an evidence-upload fix worth taking straight away.